Hi Hamna,
I don't think there is a way to restrict file types specifically on private files, because they are only available to the individual who uploaded them.
If you think you have identified any security issues, it would be great if you are able to submit them to our Security Submission Form so we can investigate further.